CrowdStrike reports 4% rise in intrusion activity as attackers move across AI, cloud and identity systems

CrowdStrike’s report tracks activity between July 1, 2025 and June 30, 2026, including attacks involving AI, software supply chains, vishing, cloud services and physical access

Staff Writer
Artifical Intelligence AI
Image: Canva

Article summary

AI Generated

CrowdStrike's 2026 Threat Hunting Report finds AI has become a core component of adversary operations, with state-linked actors exploiting vulnerabilities within 24 hours and cloud-targeting activity surging 171%. Supply chain attacks are migrating into AI frameworks, and authentication abuse is rising sharply.

Key points

  • China-nexus actors exploited vulnerabilities within 24 hours of PoC release
  • Cloud-conscious eCrime activity surged 171% in the first half of 2026
  • DPRK-linked group poisoned 131 trusted AI framework packages via npm

Subscribe to our free newsletter to continue reading.

Newsletters

CrowdStrike recorded a 4 per cent rise in intrusion activity during the 12 months to 30 June 2026 as attackers moved between identity systems, endpoints, cloud platforms, software services and developer environments, according to its 2026 Threat Hunting Report.

The increase followed a 27 per cent rise during the previous reporting period. eCrime groups accounted for 56 per cent of intrusions covered by the report, while nation-state groups accounted for 44 per cent. The figures, adversary names and attributions in this article are CrowdStrike’s findings.

CrowdStrike said its OverWatch operation analysed seven trillion events each day across endpoints, identity systems, cloud environments and security information and event management systems. The process generated 14 million detection leads each day and about 36,000 customer notifications and alerts each year.

More than one million detection and prevention opportunities were returned to the Falcon platform during the reporting period, the company said. CrowdStrike tracked more than 290 adversaries and more than 150 activity clusters and threat groups. More than 10 adversaries received names during 2026, including ALTERED SPIDER.

AI becomes a tool, target and attack route

CrowdStrike said AI-enabled adversary activity rose 89 per cent during 2025.

Advertisement

“AI is now a tool, a target, and a force multiplier for adversaries,” the report said.

The company said attackers used AI to create code, scripts, websites, job applications, development projects and messages. They also sought access to AI accounts, models and infrastructure to obtain data, run operations or transfer computing costs to victims.

CrowdStrike mapped the activity against the MITRE ATT&CK and MITRE ATLAS frameworks. Command and Scripting Interpreter, System Owner or User Discovery and Masquerading were among the ATT&CK techniques recorded in intrusion investigations.

The company said attackers used command tools to execute code, identify accounts, inspect systems and move between services. Masquerading included the use of names, files and processes intended to resemble software or user activity.

Under MITRE ATLAS, CrowdStrike recorded activity involving Resource Development, Initial Access, AI Model Access and Impact.

FAMOUS CHOLLIMA used generative AI to produce websites, GitHub accounts and email material for information technology worker operations, the report said. Other groups used language models to produce scripts, reverse shells and credential-harvesting tools.

Advertisement

Attackers also used AI development tools as routes into organisations. CrowdStrike cited software supply-chain operations, drive-by compromise and development projects containing code that executed when opened.

LLM-jacking transfers computing costs

Cost Harvesting was the MITRE ATLAS impact technique recorded most often during the reporting period.

In an LLM-jacking case from May 2026, an actor gained access to a cloud identity connected to a language-model service. CrowdStrike said the actor tested account permissions and model access before sending nearly 200,000 application programming interface requests during a two-minute period.

The service applied throttling controls. The actor then changed request rates, prompts and models while testing whether access remained available. CrowdStrike said the activity could have caused service costs for the account owner and could also have affected service availability.

Technology remains the sector with the most intrusions

Advertisement

The technology sector recorded more intrusions than any other sector for a fifth year, according to the report. Activity against technology organisations rose 5 per cent.

Consulting and professional services, financial services, manufacturing, healthcare, retail, government, telecommunications, academic institutions and industrial organisations also appeared in CrowdStrike’s sector ranking.

FAMOUS CHOLLIMA accounted for 55 per cent of nation-state intrusions and 44 per cent of all intrusions involving the technology sector, CrowdStrike said.

The group used information technology worker operations to seek access to companies in North America, Europe and Asia. CrowdStrike said the operations could provide income, information and access to company systems.

PUNK SPIDER, MUTANT SPIDER and HERALD SPIDER were among the eCrime groups linked to ransomware activity in the technology sector. Almost 54 per cent of technology-sector targeting affected organisations in North America.

Financial-services intrusions rise 11%

Advertisement

Intrusion activity against financial services rose 11 per cent. eCrime groups accounted for 57 per cent of the sector’s activity, while nation-state groups accounted for 43 per cent.

CrowdStrike said eCrime intrusion volume targeting financial services rose 29 per cent. Nation-state intrusion volume against the sector rose 26 per cent.

FAMOUS CHOLLIMA and STARDUST CHOLLIMA pursued financial-technology and cryptocurrency organisations. LOCKBIT, PLAY, LIMP SPIDER, PLUMP SPIDER and MUTANT SPIDER were among the groups linked to eCrime operations against financial organisations.

The report said attackers sought payment access, data, cryptocurrency and routes into financial systems. Forty-eight per cent of financial-sector targeting affected organisations in North America.

Intrusions against academic institutions rise 17%

Academic institutions recorded a 17 per cent increase in intrusion activity.

Advertisement

eCrime groups accounted for 55 per cent of the activity, while nation-state groups accounted for 45 per cent. CrowdStrike said the targets included research, intellectual property, student records, health data, financial information and access to partner organisations.

FAMOUS CHOLLIMA, MUSTANG PANDA, STATIC KITTEN and VAULT PANDA were among the groups linked to activity against academic institutions.

Sixty per cent of the targeting affected institutions in North America. South-East Asia accounted for 11 per cent and the Middle East accounted for 8 per cent.

Exploitation starts within hours of public disclosure

CrowdStrike recorded a 42 per cent year-on-year increase in zero-day exploitation between 2024 and 2025.

From January to June 2026, 88 per cent of observed exploitation involving vulnerabilities with public proof-of-concept code occurred within 48 hours of the code’s release, the report said.

Advertisement

The company said the period between disclosure and exploitation was shrinking as attackers used automation and AI during vulnerability research and exploit development.

React2Shell generates more than 800 hunting leads

The report examined React2Shell, identified as CVE-2025-55182, a remote-code-execution vulnerability affecting React Server Components and Next.js applications.

CrowdStrike said OverWatch responded to more than 800 hunting leads linked to suspected React2Shell exploitation across more than 80 victims.

Within 24 hours of public disclosure, VAULT PANDA, GENESIS PANDA and actors without attribution began exploitation attempts.

VAULT PANDA used the vulnerability to deploy a GoDoner implant disguised as a Linux utility, according to the report. GENESIS PANDA used React2Shell to deploy tools including VShell and SempathyRAT. CrowdStrike said the group conducted operations across sectors and regions.

Advertisement

CopyFail activity appears after disclosure

CrowdStrike also examined CopyFail, a Linux privilege-escalation exploit linked to CVE-2026-31431.

A proof of concept was released on 29 April 2026. By 30 April, OverWatch had detected deployment of the exploit.

About 94 per cent of the events during the first 24 hours appeared to involve testing based on public code, the report said. CrowdStrike said its hunters later found activity linked to a Belarus-nexus actor just over 20 hours after public disclosure.

The company said defenders had to distinguish security testing from intrusion activity while an exploit was spreading.

Software supply-chain attacks target developer ecosystems

Advertisement

CrowdStrike identified five trends in software supply-chain operations:

  1. Attackers are targeting developer ecosystems.
  2. Operations are using automation and scale.
  3. Identity remains an entry point.
  4. Continuous integration and delivery pipelines are targets.
  5. Attackers are moving from software systems into cloud environments.

The report said npm, PyPI, GitHub Actions, container registries, source-code repositories, browser extensions, development tools and package-maintainer accounts provided routes into organisations.

A compromise involving one account or package could distribute code across projects, customers and production environments, CrowdStrike said.

FAMOUS CHOLLIMA uses development projects

FAMOUS CHOLLIMA built repositories and project files that appeared to support cryptocurrency and blockchain development, the report said.

Advertisement

When developers opened some projects, task runners, terminal functions or installation processes executed commands and installed malware. CrowdStrike described this as a supply-chain operation because the attack used development material as the delivery route.

ALTERED SPIDER compromises software dependencies

ALTERED SPIDER used automation to distribute TeamPCPCloudStealer through npm and PyPI.

CrowdStrike said the operation compromised more than 300 software dependencies during one day in May 2026.

The malware searched for cloud-access keys, Microsoft Azure credentials, Google Cloud tokens, Kubernetes service-account tokens, Secure Shell keys, pipeline secrets, container-registry credentials and cryptocurrency-wallet keys.

It also collected information about containers, repositories, development systems and cloud accounts.

Advertisement

CrowdStrike said ALTERED SPIDER used stolen package credentials, automated publishing and code changes to move across software and cloud systems. The company’s report presents a diagram showing how OverWatch traced the activity between source repositories, cloud environments and identity systems.

Trivy repository targeted through a stolen token

ALTERED SPIDER compromised the Trivy source-code repository in March 2026 through a stolen personal access token, according to the report.

The actor changed GitHub Actions workflows and used Git tag poisoning. CrowdStrike said the changes were intended to collect credentials and place code into build processes.

The case showed how a repository account could provide access to software releases, development workflows and cloud identities.

AI ecosystems may become supply-chain targets

Advertisement

CrowdStrike said AI development frameworks, model registries, plugins, tools and agent systems were becoming part of software supply chains.

The report said these systems could provide attack routes when organisations placed them in development and deployment workflows. It called AI ecosystems “the next software supply chain battleground”.

Vishing intrusions rise 134%

Intrusions involving voice phishing rose 134 per cent between 2024 and 2025, CrowdStrike said.

The first half of 2026 recorded twice as many vishing intrusions as the first half of 2025.

Attackers used calls to persuade users to disclose credentials, approve authentication requests, register devices or install remote-access software. CrowdStrike said much of the activity took place through identity providers, mobile devices and SaaS platforms rather than managed endpoints.

Advertisement

CORDIAL SPIDER and SNARKY SPIDER target SaaS accounts

CORDIAL SPIDER and SNARKY SPIDER used vishing and adversary-in-the-middle pages to collect single sign-on credentials and authentication codes, the report said.

The groups used residential proxy services and virtual private networks to make login locations resemble those of account holders. They also registered phones and emulators, including QEMU and Genymotion devices, with identity systems.

After obtaining access, the actors entered Microsoft 365, Google Workspace and other SaaS applications. They searched files, messages and account data, according to CrowdStrike.

In one February 2026 case, OverWatch observed a user answer a call, authenticate through a phishing page and register another authentication device.

CrowdStrike said its analysts contained the account before the actor completed the operation. The report’s timeline shows that the activity moved from the call to account access within minutes.

Advertisement

CrowdStrike recommended phishing-resistant authentication such as FIDO2, checks for device enrolment, monitoring for travel conflicts and emulator use, and alerts for file downloads from locations that do not match account history.

It also said employees should not act on calls to personal devices from people claiming to represent an information technology department unless the organisation requires that process.

OAuth phishing targets Microsoft Entra ID accounts

CrowdStrike said nation-state groups had abused OAuth 2.0 flows to target Microsoft Entra ID accounts since at least February 2025.

The methods included device-code phishing, consent phishing and applications designed to collect access tokens.

In a device-code operation, an attacker gives a code to a victim and directs that person to a service login page. The victim completes authentication with the service, while the attacker receives access through the authorised session.

Advertisement

The report also referred to phishing-as-a-service operations including EvilTokens and Kali365.

In April 2026, COZY BEAR contacted a target at a UK-based think tank through WhatsApp, CrowdStrike said. The operation used OAuth device-code phishing.

After the target completed authentication, the actor obtained access to SharePoint and email data. CrowdStrike said the campaign reflected methods used by the group for intelligence collection.

Cloud-conscious eCrime activity rises 171%

CrowdStrike recorded a 171 per cent increase in cloud-conscious eCrime activity during the preceding 12 months.

Attackers used cloud accounts and infrastructure for cryptocurrency mining, payment theft, data collection and access to financial assets.

Advertisement

CrowdStrike estimated that resource hijacking could produce computing costs ranging from $10,000 to more than $100,000. The report also cited payment-system theft involving millions of dollars, data theft, business disruption and recovery costs.

SLIM SPIDER targets Pix and cryptocurrency infrastructure

SLIM SPIDER targeted systems connected to Brazil’s Pix payment network and cryptocurrency infrastructure, according to the report.

CrowdStrike said the group used credentials, cloud metadata and infrastructure tools to locate financial assets.

The group’s tooling included NEXUS, an API-scanning panel; an email-search panel for Microsoft 365 mailboxes; and a programming interface browser used to access information through compromised accounts.

Mining campaign targets US technology company

Advertisement

On 8 January 2026, CrowdStrike detected an actor using cloud resources at a US technology company for cryptocurrency mining.

The actor deployed XMRig through containers and used generated container names, encoded configuration files, cross-account roles and several execution routes.

CrowdStrike said the actor attempted to preserve access and continue the mining operation if one route was blocked.

The company said cloud detection should examine behaviour rather than rely only on credentials, addresses or location data. It recommended monitoring control-plane activity, identities, containers, serverless functions, APIs and changes across cloud accounts.

OVERCAST PANDA uses physical access during business travel

CrowdStrike documented close-access operations attributed to OVERCAST PANDA, a China-nexus group.

Advertisement

The company said the group used physical proximity, portable media and malware called FlowCloud and LockRock to bypass network controls.

CrowdStrike associated the activity with victims from Japan, Taiwan, the United States and the United Kingdom. Target sectors included agriculture, energy, hospitality, law, logistics, media, non-profit organisations, technology and utilities.

Between March and May 2026, CrowdStrike identified operations involving employees travelling in China.

One case involved workers from a US agricultural biotechnology company attending a conference in Hainan. CrowdStrike said FlowCloud was placed on employee devices through USB access.

The report said the operator may have accessed devices when they were left without supervision in a hotel, conference setting or travel environment.

FlowCloud checked devices for security software, created persistence, contacted command infrastructure through cloud services and collected files, CrowdStrike said. The malware could also use USB devices to move data.

Advertisement

The company linked victim selection to sectors covered by China’s Five-Year Plans, including agricultural biotechnology, human genetics, seed production and research.

CrowdStrike recommended full-disk encryption with pre-boot authentication, removal of Wi-Fi auto-connect functions, BIOS or UEFI passwords, limits on research data stored on travel devices, custody controls, travel briefings and USB restrictions.

CrowdStrike sets seven defence priorities

CrowdStrike said attackers no longer operated within one security domain. Instead, they moved through identity systems, endpoints, SaaS applications, cloud platforms, software development environments and physical-access routes.

“It is not enough to respond; defenders must anticipate, pivot, and relentlessly pursue the adversary,” the report said.

The company set seven recommendations:

Advertisement
  1. Secure AI systems: Control access to AI models, APIs, agents and development environments, monitor AI use and include AI-related events in response plans.
  2. Treat identity and SaaS as attack surfaces: Use phishing-resistant authentication, monitor sign-ins and device registrations, and collect SaaS records.
  3. Remove gaps between security domains: Combine endpoint, identity, cloud, SaaS and application data during detection and response.
  4. Protect software supply chains: Secure repositories, dependencies, package accounts, signing systems, pipelines and development credentials.
  5. Reduce the attack surface: Find internet-facing vulnerabilities, unused services, configuration errors, unmanaged assets and unapproved AI systems.
  6. Use threat intelligence and hunting: Search for campaign activity before an alert or incident occurs.
  7. Prepare for social engineering: Use staff training, tabletop exercises, red-team work and response rehearsals.

Report includes CrowdStrike product and service listings

The final nine pages contain information about CrowdStrike’s Falcon platform, products and services.

The categories cover endpoint security, adversary operations, cloud security, SaaS security, AI detection and response, identity security, browser security, next-generation SIEM, data security, asset management, information technology operations and managed detection and response.

The report also lists incident response, adversary services, red-team exercises, AI security assessments, identity assessments, cloud assessments, platform services, training and consulting.